Advise · System Audits

You can't manage what you haven't measured.

An engineer-led audit of your technology as it actually is — infrastructure, security, network, Microsoft 365, compliance, cameras, software — scored against a standard and written up with priorities and costs. Yours to keep, whoever does the work.

Most businesses have never seen an honest inventory of what they run, what it costs, and where it will fail. That inventory is the start of every good decision.

Why audit

Great measurements make even better management.

It's the principle behind every platform we build, and it applies to your technology estate too. Before you buy, migrate, renew or sign a contract, know what you have, what it costs, what it's exposed to, and what will fail first. An audit turns "I think" into "I know".

Scored against a standard

Every finding is rated for risk and effort against a published checklist — CIS controls for security, Microsoft best practice for 365, the POPIA conditions for data — so the score means the same next year.

Independent by design

The audit is priced on its own and the report is written for anyone to act on. You're buying a clear view, not a sales funnel.

Prioritised, costed, dated

A fix-first list with indicative costs and a 90-day / 12-month roadmap. Short enough for a board pack; detailed enough for an engineer.

Audit types

Seven audits. Combine what fits.

IT infrastructure & DR

Servers, storage, virtualisation, backups and the honest answer to "can we restore?"

  • Asset and licence inventory
  • Backup coverage and a real restore test
  • Warranty, age and single points of failure
  • Load-shedding and power resilience
Any business with a server room

Cyber-security posture

Where you're exposed and what an attacker would find first.

  • External attack surface and exposed services
  • Identity, MFA, privileged accounts
  • Endpoint protection, patch state, email security
  • Scored against CIS Controls
Everyone · required by most cyber insurers

Network & connectivity

Topology, redundancy, Wi-Fi and the links you depend on.

  • Discovered topology and IP plan
  • Single points of failure, failover test
  • Wi-Fi coverage and segmentation (VLANs)
  • Link performance: latency, jitter, loss
Multi-site · VoIP · cameras

Microsoft 365 & licensing

Configuration, security and whether you're paying for the right licences.

  • Licence usage vs. spend, consolidation options
  • Secure Score, conditional access, MFA
  • Retention, DLP, mailbox backup
  • Teams, SharePoint and OneDrive governance
Any M365 tenant · see M365 services

Compliance readiness

Technology controls behind your regulatory obligations.

  • POPIA conditions mapped to systems
  • FICA record-keeping and retention
  • FSCA / LPC / SAICA data and access rules
  • Evidence pack for auditors and insurers
FSPs · legal · accounting · medical

CCTV & physical security

Are the cameras, access control and alarms actually doing their job?

  • Camera coverage, quality and retention
  • Recorder health, remote access, firmware
  • Access control, alarms, response SOPs
  • Evidence usability for insurers and SAPS
Estates · warehouses · retail · plants

Software & database health

The line-of-business system everything depends on — and nobody dares touch.

  • Code, framework and dependency age
  • Database performance, backups, integrity
  • Integration map and data flows
  • Modernise, replace or consolidate — with numbers
Custom and legacy systems
What you get

A report that gets used, not filed.

01Executive summary

One page. Overall score, top five risks, what to do this quarter.

02Inventory

Everything you run — hardware, software, licences, links, contracts — and what it costs.

03Scored findings

Each item rated for risk and effort against the standard, with evidence.

04Roadmap & costs

90-day fix list and 12-month plan with indicative pricing.

05Walkthrough

An hour with the engineer who wrote it, for your team or your board.

How it runs

Scoped, measured, written, walked through.

Scope

20-minute call. Which audits, which sites, who to interview. Fixed price agreed.

Discover

Read-only tooling deployed, documents collected, short interviews, site visit where needed.

Score & write

Findings rated against the standard; roadmap and costs assembled; report reviewed by a second engineer.

Walk through

Presented to you or your board. Questions answered. Report is yours.

Questions we get asked

Straight answers.

How is an audit different from the free health check?

The health check is a 30-minute to two-hour engineer's read on your environment with a short written summary. An audit is a scoped, measured exercise — days, not hours — with tooling deployed, evidence collected, findings scored against a standard, and a board-ready report with a prioritised roadmap and indicative costs.

Which audits do you offer?

IT infrastructure and backup/DR; cyber-security posture; network and connectivity; Microsoft 365 configuration, licensing and compliance; regulatory readiness for POPIA, FICA, FSCA and LPC obligations; CCTV, access control and physical security systems; and software/database health for line-of-business systems. Most customers combine two or three.

Do we have to use Swiss Systems to fix what you find?

No. The report is written so any competent provider can act on it — that's the point of paying for an independent view. Many customers do ask us to fix the top items, and the audit becomes the scope for that work, but there is no obligation.

Will an audit disrupt the business?

No. Discovery tooling is read-only and outbound, interviews are short, and site visits are scheduled. Nothing is changed during an audit; recommendations are actioned only when you approve them.

How is it priced?

Fixed price per audit type and site size, quoted after a 20-minute scoping call. The free health check is often enough to decide whether a full audit is worth it — we'll tell you if it isn't.

Can it be repeated annually?

Yes, and it should be. Annual re-audits score the same items so you see the trend, and they double as evidence for insurers, auditors, regulators and clients who ask how your technology is controlled.

Part of the Swiss service model

Advise. Build. Host. Connect. Run.

Every service sits in one of four lines and runs under the same SLA: 15-minute P1 response, 99.9% hosted uptime, named engineers, monthly reporting, service credits if we miss. See the SLA in numbers →

00 · Advise Measure first, then decide
01 · Build Software that fits the operation
02 · Host Our data centre, your workloads
03 · Connect Sites, people and phones, joined up
04 · Run Managed, monitored, accountable
Ready when you are

Get the honest inventory.

A 20-minute scoping call tells you which audit fits and what it costs. If the free health check is enough, we'll say so.

01

Measured, not opinion

Tooling, evidence and a scoring standard. Findings you can show a board or an auditor.

02

Prioritised and costed

Fix-first list with risk, effort and indicative cost. No 200-page PDF nobody reads.

03

Yours to keep

Use it with us or with anyone else. Independence is what you're paying for.